Coldcard Flaw Exposes Hundreds of Bitcoin Wallets to Attack
A security flaw in Coldcard firmware allowed an attacker to drain around $38 million from approximately 500 Bitcoin wallets over a period of 25 minutes. The affected devices were mostly Mk3, with some Mk4 and Q models also impacted.
The vulnerability exploited the fact that the devices' hardware random number generator was being bypassed in favor of software-generated randomness. This allowed an attacker to guess seed phrases that should have been unguessable due to their immense complexity.
Coldcard's advisory warns users to move their funds immediately, as updating firmware will not retroactively fix compromised seeds. The company also recommends generating a fresh wallet on a trusted device and moving funds there.